Got a search which is slow.
When I click the job inspector, see all the time spend on different components. Is it possible to save all those information for later analysis as it take more than 1 hr to repro / run the search each time.
When click 'Inspect Job', you'll get a SID. For example, SID: 1554349211.28387
You can ssh to the splunk box and go to below directory
/opt/splunk/var/run/splunk/dispatch/1554349211.28387
Then, create a file called 'save' and Splunk will not remove that directory (You may need to remove that directory later after invesgitation).
# touch save
Moreover, you can tar the above directory and transfer to our host for further analysis also.
The search inspector log can be viewed as:
http://localhost:8000/en-US/manager/search/job_inspector?sid=1554349211.28387